CWE-131
High likelihoodIncorrect Calculation of Buffer Size
Parent: CWE-682 - Incorrect Calculation
The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.
209 vulnerabilities with CWE-131
CVE-2026-45812
MEDIUM
Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler
CVSS 6.5
CVE-2026-65706
HIGH
FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing
CVSS 7.8
CVE-2026-65705
HIGH
FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()
CVSS 7.8
CVE-2026-45784
HIGH
rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers
CVSS 7.1
CVE-2026-55827
HIGH
FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode
CVSS 7.5
CVE-2026-0280
HIGH
PAN-OS: IPv6 Firewall Policy Bypass
CVSS 7.2
CVE-2026-54696
LOW
Ruby JSON: JSON generator heap buffer overflow when streaming to an IO
CVSS 3.7
CVE-2026-53143
HIGH
drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVSS 7.8
CVE-2026-2050
HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-53091
HIGH
net: pull headers in qdisc_pkt_len_segs_init()
CVSS 8.4
CVE-2026-52955
CRITICAL
libceph: Fix potential out-of-bounds access in crush_decode()
CVSS 9.8
CVE-2026-42055
HIGH
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
CVSS 8.1
CVE-2026-8357
HIGH
The Document Foundation LibreOffice - Heap Buffer Overflow in Calc Formula Compilation
CVSS 7.8
CVE-2026-46521
MEDIUM
ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression
CVSS 5.5
CVE-2026-2049
HIGH
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-11604
MEDIUM
Openvpn Ovpn-dco-win < 2.5.8 - Heap-based Buffer Overflow
CVE-2026-49841
CRITICAL
FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read
CVSS 9.8
CVE-2026-42915
MEDIUM
Microsoft Windows TCP/IP - Authorized Adjacent Network Denial of Service
CVSS 5.5
CVE-2026-10701
HIGH
Incorrect boundary conditions in the Graphics: Text component
CVSS 7.5
CVE-2026-44420
HIGH
FreeRDP cliprdr server heap-buffer-overflow via undersized capabilitySetLength in CB_CLIP_CAPS
CVSS 8.8
CVE-2026-43501
CRITICAL
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
CVSS 9.8
CVE-2026-42945
HIGH
NGINX Plus and NGINX Open Source - Heap-based Buffer Overflow in ngx_http_rewrite_module
CVSS 8.1
CVE-2026-40618
HIGH
F5 BIG-IP SSL/TLS - TMM Denial of Service
CVSS 7.5
CVE-2026-44223
MEDIUM
vLLM: extract_hidden_states speculative decoding crashes server on any request with penalty parameters
CVSS 6.5
CVE-2026-43302
MEDIUM
drm/v3d: Set DMA segment size to avoid debug warnings
CVSS 5.5
Details
Vulnerabilities
209
Exploit Likelihood
High